CVE Database
/

CVE-2018-5131

Back to search

CVE-2018-5131

Published: Jun 11, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while browsing. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

VendorProductVersions

Mozilla

Firefox ESR

affected
unspecified - < 52.7

Mozilla

Firefox

affected
unspecified - < 59

References

DSA-4139
vendor-advisory
x_refsource_DEBIAN
GLSA-201810-01
vendor-advisory
x_refsource_GENTOO
103388
vdb-entry
x_refsource_BID
RHSA-2018:0527
vendor-advisory
x_refsource_REDHAT
RHSA-2018:0526
vendor-advisory
x_refsource_REDHAT
1040514
vdb-entry
x_refsource_SECTRACK
USN-3596-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now